Cross Site Scripting Vulnerability in D-Link DIR-816 by D-Link
CVE-2025-1392

5.1MEDIUM

Key Information:

Vendor
D-link
Status
Vendor
CVE Published:
17 February 2025

Summary

A vulnerability exists in the D-Link DIR-816 router, specifically in the functionality accessed through /cgi-bin/webproc?getpage=html/index.html&var:menu=24gwlan&var:page=24G_basic. By manipulating the SSID argument, an attacker can execute cross site scripting attacks remotely. This vulnerability affects devices that are no longer supported by D-Link, allowing potential exploitation due to its public disclosure.

Affected Version(s)

DIR-816 1.01TO

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Fergod (VulDB User)
.